CISA guidance for federal agencies: BODs, CDM, and zero trust
How federal agencies implement CISA binding operational directives, CDM, and the zero-trust mandate — and where contractors fit.
Federal civilian agencies don't get to choose: CISA's Binding Operational Directives are compulsory, OMB M-22-09 set the zero-trust deadline architecture, and the CDM program provides the tooling. This guide is the implementation map.
The mandatory stack
- BOD 22-01: remediate KEV-catalog vulnerabilities on CISA's timelines.
- BOD 23-01: maintain asset inventories and vulnerability disclosure programs.
- OMB M-22-09: federal zero-trust strategy with defined pillars and milestones, aligned to CISA's Zero Trust Maturity Model.
- CDM: Continuous Diagnostics and Mitigation — the DHS program supplying agency dashboard and sensor tooling.
Where contractors fit
Agencies buy implementation through vehicles: vulnerability-management operations, zero-trust architecture and migration, and CDM integration support. Firms in our directory tagged for the federal stage — GuidePoint Security, ECS, Guidehouse, Booz Allen, CACI, Presidio — work this stack daily.
Budget reality
Directive compliance is funded from agency operations budgets, not a separate “CISA fee.” Planning ranges for the contracted pieces are in our cost guide — and CISA's own scanning services are free to agencies.
Get quotes from firms that do this work
Matched to your sector and scope — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.